Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms pages via the REST API without authorization.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: adobe
Published: 2020-11-09T00:40:04.994192Z
Updated: 2024-09-16T17:47:57.272Z
Reserved: 2020-08-19T00:00:00
Link: CVE-2020-24404
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-11-09T01:15:12.707
Modified: 2024-11-21T05:14:45.423
Link: CVE-2020-24404
Redhat
No data.